Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The thing is, anything but passwords is extremely challenging for non-tech users.

People usually manage to not loose/destroy the keys to their houses/cars very often. A FIDO token is very similar. You just need to understand that it's important to not loose it and that you should have a second backup key. I don't think this problem has anything to do with being a "non-tech" user.



> People usually manage to not loose/destroy the keys to their houses/cars very often.

Lol. Friend of mine works in real estate... losing keys is very common.

> You just need to understand that it's important to not loose it and that you should have a second backup key.

And how many people have that? Know that? Don't skip the dialog warnings because they've been conditioned to do so? And on top of that, what about the services that only support one 2FA device like Amazon AWS with Yubikeys?


> Lol. Friend of mine works in real estate... losing keys is very common.

Ok, fair point. That's why it'd be good to have a second key somewhere safe. The FIDO token also is just one key that can be used for multiple websites. That's like having many houses and all can be unlocked with one key.

> And how many people have that? Know that? Don't skip the dialog warnings because they've been conditioned to do so?

I don't know, you're right perhaps not that many. But the problem is maybe also that people do not want to pay ca. 60$ for two yubi-keys just to be able to use the same websites their using with a password already. Perhaps the passkeys login using android/ios (e.g. authentication via fingerprint with your smartphone) is going to be much more popular because it's more convenient and "free" (except you pay with your data).

> And on top of that, what about the services that only support one 2FA device like Amazon AWS with Yubikeys?

Yeah, services that do that or even have 2FA as a paid-only feature need to change that. It's just a system flaw on their side in my eyes. Hopefully, such bad practices will bring those services a big enough competitive disadvantage in the future that they're forced to implement 2FA properly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: